Vulnerabilities
Summary — last 7 days
New vulnerabilities2,661▼ 437 vs. last week
Critical / high1,284▼ 85 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)247▼ 271 vs. last week
112 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9) | 1.6% | — | Rymera WEB CO PTY LTD Woocommerce Wholesale Lead CaptureAI | 3/19/2026 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. | |
| Deferred | Critical (9.3) | 0.43% | — | Kamleshyadav WP Lead CaptureAI | 1/22/2026 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5. | |
| Deferred | High (8.5) | 0.42% | — | Kamleshyadav WP Lead CaptureAI | 1/22/2026 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affects WP Lead Capturing Pages: from n/a through <= 2.5. | |
| Analyzed | Medium (6.9) | 0.14% | — | Milner Imagedirector Capture | 1/20/2026 | 6/17/2026 | Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key. This issue affects ImageDirector Capture: from 7.0.9.0 before… | |
| Analyzed | High (7.2) | 0.08% | — | Milner Imagedirector Capture | 1/20/2026 | 6/17/2026 | Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brute Forcing to obtain database credentials.This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808. | |
| Analyzed | High (8.5) | 0.18% | — | Milner Imagedirector Capture | 1/20/2026 | 6/17/2026 | Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects… | |
| Analyzed | High (8.5) | 0.19% | — | Milner Imagedirector Capture | 1/20/2026 | 6/17/2026 | Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This issue affects ImageDirector Capture: from 7.0.9 through 7.6.3.25808. | |
| Analyzed | High (8.5) | 0.07% | — | Milner Imagedirector Capture | 1/20/2026 | 6/17/2026 | The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before… | |
| Deferred | Medium (4.3) | 0.13% | — | Winwar WP Email CaptureAI | 12/24/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Cross Site Request Forgery.This issue affects WP Email Capture: from n/a through <= 3.12.5. | |
| Analyzed | Medium (6.1) | 0.29% | — | Clincapture Captivate Electronic Data Capture | 12/22/2025 | 6/17/2026 | Reflected cross-site scripting (XSS) vulnerability in ClinCapture EDC 3.0 and 2.2.3, allowing an unauthenticated remote attacker to execute JavaScript code in the context of the victim's browser. | |
| Deferred | Medium (5.3) | 0.25% | — | Winwar WP Email CaptureAI | 12/9/2025 | 6/17/2026 | Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4. | |
| Analyzed | High (7.8) | 0.23% | — | Electroncapture Electron Capture | 8/5/2025 | 6/17/2026 | Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e… | |
| Deferred | Medium (4.3) | 0.17% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 5/7/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Cross Site Request Forgery.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.8. | |
| Deferred | High (7.1) | 0.29% | — | Syedbalkhi Beacon Lead Magnets AND Lead CaptureAI | 4/17/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Beacon Lead Magnets and Lead Capture beacon-by allows Reflected XSS.This issue affects Beacon Lead Magnets and Lead Capture: from n/a through <= 1.5.7. | |
| Deferred | Medium (6.5) | 0.18% | — | Recapture FOR WoocommerceAI | 3/15/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce allows Cross Site Request Forgery.This issue affects Recapture for WooCommerce: from n/a through <= 1.0.43. | |
| Deferred | High (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 3/13/2025 | 6/17/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 are vulnerable to an attacker impersonating the web application service and mislead victim clients. | |
| Deferred | Critical (9.3) | 0.45% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 3/13/2025 | 6/17/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed web management service that could allow an attacker to bypass authentication measures and gain controls over utilities within the products. | |
| Deferred | High (8.7) | 0.39% | — | Optigo Networks Visual Bacnet Capture ToolAIOptigo Networks Visual Networks Capture ToolAI | 3/13/2025 | 6/17/2026 | Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain a hard coded secret key. This could allow an attacker to generate valid JWT (JSON Web Token) sessions. | |
| Deferred | Medium (4.3) | 0.25% | — | Wishfulthemes Email Capture AND Lead GenerationAI | 1/16/2025 | 6/17/2026 | Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation email-capture-lead-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through <= 1.0.2. | |
| Deferred | Medium (4.3) | 0.31% | — | SMS FOR Lead Capture FormsAI | 12/7/2024 | 6/17/2026 | The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_message() function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Modified | Medium (5.9) | 0.30% | — | IBM Qradar Network Packet Capture | 8/15/2024 | 6/17/2026 | IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modified | Medium (5.5) | 0.21% | — | Sonicwall Capture ClientSonicwall Netextender | 1/18/2024 | 6/17/2026 | SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability. | |
| Modified | Medium (5.4) | 0.34% | — | Tungstenautomation Kofax Capture | 1/11/2024 | 6/17/2026 | The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author and text are not adequately sanitized and validated. This allows for the injection of malicious JavaScript code. The… | |
| Modified | High (7.5) | 0.55% | — | Winwar WP Email Capture | 12/21/2023 | 6/17/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10. | |
| Modified | Critical (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 6/14/2023 | 6/17/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. |